https://developer.apple.com/documentation/security/disabling...
The fact that the phone manufacturer has a more privileged access than the owner of the phone is absolute insanity.
It's not even about lies. It's about bugs and vulnerabilities, which every vendor has.
It's a perfectly fine decision, but Linux was, and still is, an option for plenty of people who develop for Apple hardware/software without daily driving it, myself included.
Well, I believe in dogfooding. I don't think it would be good for my software or my customers if I didn't use the same operating system as them. Besides, work-related activities are mostly what I use a computer for, so I'm not sure what I would even do with Linux.
Again, full respect for your decisions, but there are consequences to them and as your blog and experience shows, they are numerous and have serious impacts.
You: You'd be more in control over having your passwords silently uploaded to a third party without your knowledge or consent
If I mostly use a computer for work purposes, what do you think my passwords are for?
Also, I've been using a Mac since 2002, and iCloud Keychain got toggled on in 2024. It's kind of absurd to suggest, in 20/20 hindsight, that I should have expected it.
Do your thing buddy, but I'm not the one who had their (work) passwords were silently uploaded to iCloud without permission.
How many times do I have to explain that I use a computer mostly to do work, which is development of Apple software, requiring a Mac, and therefore most of my computer usage is necessarily on a Mac. Consequently, switching to a Linux machine as a "daily driver" is pointless, because I have nothing much to "drive" daily except my work.
Authentication: "Prove you are you" (hash functions)
Secure Storage: "Keep this secret but let me get it back later" (encryption)
Identification: "Track who/what this is" (UUIDs/tokens)
Password managers—all password managers—require stored passwords to be encrypted such that they can be decrypted. Otherwise they would have no possibly way to retrieve the stored secret for the sake of submitting it to the verifying party.
Best practice for verifiers is to use a one-way memory-hard password hash.
Keychain is a password manager.
This is what keychain does. You retrieve the passwords later.
So, no. It is not a one-way hash function as you stated.
Use Argon2 to hash a password before storing it in the password manager. Now the user visits that website and wants to log in. What is it that the password manager pastes into the login form?
Answer: the plaintext password. But how do you get that out of the hashed value you stored earlier? You don’t. Ergo, password managers cannot use hashing functions to store their contents.
Next time you insult someone, better use your cognition powers to avoid looking like that which you call others
By GP, u/blitzar's comment, my cognition tells me that his comment meant anyone can break AES 256-bit encryption, including Apple, but in this context, he could have meant everyone else
One for password key column, one for value column and one for the password file.